On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Microsoft’s weasel-word response to the State Department email hackJumpCloud got owned, maybe by DPRKCitrix 0day is getting stuff rektTwo more spyware firms sanctioned by USAScammers list fake phone numbers for major airlines on Google MapsMuch, much moreThis week’s show is brought to you by security focussed enterprise browser maker Island. Dan Amiga, Island’s CTO and co-founder, is this week’s sponsor guest. He talks about why widespread enterprise browser deployment is inevitable.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
China-based hackers breach email accounts at State DepartmentMicrosoft hardens key issuance systems after state-backed hackers breach Outlook accounts | Cybersecurity DiveMicrosoft takes pains to obscure role in 0-days that caused email breach | Ars TechnicaStealth Mode: Chinese Cyber Espionage Actors Continue to Evolve Tactics to Avoid Detection | MandiantHackers target Pakistani government, bank and telecom provider with China-made malwareRisky Biz News: JumpCloud compromised by APT groupExploited 0-days, an incomplete fix, and a botched disclosure: Infosec snafu reigns | Ars TechnicaCISA warns of dangerous Rockwell industrial bug being exploited by gov’t groupRockwell Automation, Honeywell warned of critical vulnerabilities in industrial products | Cybersecurity DiveCISA gives US civilian agencies until August 1 to resolve four Microsoft vulnerabilitiesGoogle fixes ‘Bad.Build’ vulnerability affecting Cloud Build serviceWhite House unveils consumer labeling program to strengthen IoT security | Cybersecurity DiveSenate bill crafted with DEA targets end-to-end encryption, requires online companies to report drug activityTwo more foreign spyware firms blacklisted by USPhone numbers for airlines listed on Google directed to scammersBy criminals, for criminals: AI tool easily generates ‘remarkably persuasive’ fraud emailsItamar Golan 🤓 on Twitter: "A malicious LLM-based tool known as WormGPT 🪱 is rapidly gaining traction in underground forums. This tool empowers attackers to automate sophisticated phishing and BEC (Business Email Compromise) attacks, leveraging personalized fake emails to significantly enhance success… https://t.co/fAcrYhT696" / TwitterFCC chair proposes $200M investment to boost K-12 cybersecurity | Cybersecurity DiveFed ends Capital One breach-related enforcement action | Cybersecurity DiveNorwegian Refugee Council hit by cyberattackBelarus-linked hacks on Ukraine, Poland began at least a year ago, report saysAlbania’s PM complains US is not providing country with cyberdefense fundsVirusTotal: Datenleck offenbart Kunden der Google-Sicherheitsplattform - DER SPIEGELGenesis Market sold to anonymous buyer despite FBI disruption